wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

POST-TEST DAY 3

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

John is a pen tester working with an information security consultant based in Paris. As part of a penetration testing assignment, he was asked to perform wireless penetration testing for a large MNC. John knows that the company provides free Wi-Fi access to its employees on the company premises. He sets up a rogue wireless access point with the same SSID as that of the company’s Wi-Fi network just outside the company premises. He sets up this rogue access point using the tools that he has and hopes that the employees might connect to it. What type of wireless confidentiality attack is John trying to do?

a)

KRACK Attack

b)

WEP Cracking

c)

Evil Twin AP

d)

War Driving

2.

Which of the following Encryption technique is used in WPA?

a)

DES

b)

AES

c)

TKIP

d)

RSA

3.

Which of the following is not a mobile platform risk?

a)

Malicious Apps in App Store

b)

Sandboxing

c)

Jailbreaking and Rooting

d)

Mobile Malware

4.

 

James, an attacker, attempted to gain illegitimate access to a user’s bank account. To achieve his goal, James tricked mobile phone sellers into providing PII of the target user and exploited the instant message service on the user’s device, which helped him reset the password and access the victim’s account.

Identify the type of attack performed by James in the above scenario.

a)

Brute-force attack

b)

Cross-site request forgery

c)

OTP hijacking

d)

DNS poisoning

5.

Which of the following layers in the IoT architecture has security issues such as validation of the inputted string, AuthN, AuthZ, no automatic security updates, and default passwords?

a)

Mobile

b)

Network

c)

Application

d)

Cloud

6.

Which of the following Nmap commands is used by an attacker to identify the IPv6 capabilities of a target IoT device?

a)

nmap -n -Pn -sS -pT:0-65535 -v -A -oX <Name> <IP>

b)

nmap -n -Pn -sSU -pT:0-65535,U:0-65535 -v -A -oX <Name> <IP>

c)

nmap -p 80,81,8080,8081 <Target IP address range>

d)

nmap -6 -n -Pn -sSU -pT:0-65535,U:0-65535 -v -A -oX <Name> <IP>

7.

In which of the following levels of the Purdue model can the analysis and alteration of the physical process be performed?

a)

Level 2

b)

Level 3

c)

Level 1

d)

Level 0

8.

Which of the following components of an industrial control system contains a centralized supervisory control unit used to control multiple local controllers, thousands of input/output (I/O) points, and various other field devices that are part of the overall production process?

a)

DCS

b)

BPCS

c)

SIS

d)

SCADA

9.

Which of the following three service models are the standard cloud service models?

a)

SaaS, IaaS, and hybrid

b)

XaaS, private, and public

c)

Private, public, and community

d)

SaaS, PaaS, and IaaS

10.

In which of the following cloud deployment models does the provider make services such as applications, servers, and data storage available to the public over the Internet?

a)

Hybrid cloud

b)

Community cloud

c)

Public cloud

d)

Private cloud